[PATCH] block: make blkdev_fallocate() zeroout killable

From: Nguyen Ngoc Thang

Date: Sun Sep 27 2026 - 01:15:44 EST


blkdev_fallocate() zeroes the requested range while holding i_rwsem
and invalidate_lock exclusively, but does not pass BLKDEV_ZERO_KILLABLE
to blkdev_issue_zeroout(). On a large device that falls back to
writing zero pages (e.g. null_blk), the loop keeps going after the
caller received SIGKILL, and every buffered reader of the device
blocks behind it:

rwsem_down_read_slowpath+0x61e/0x920 kernel/locking/rwsem.c:1086
down_read+0x99/0x2e0 kernel/locking/rwsem.c:1539
blkdev_read_iter+0x2f8/0x440 block/fops.c:854

syzbot reports this as a hung task. BLKZEROOUT already sets the flag
for the same reason; do the same for fallocate.

Reported-by: syzbot+afa7aef0c237038586e7@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=afa7aef0c237038586e7
Fixes: 25f4c41415e5 ("block: implement (some of) fallocate for block devices")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@xxxxxxxxx>
---
block/fops.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/block/fops.c b/block/fops.c
index 2ce7c6c4714e..a2fe27d8ceff 100644
--- a/block/fops.c
+++ b/block/fops.c
@@ -909,7 +909,8 @@ static long blkdev_fallocate(struct file *file, int mode, loff_t start,
goto fail;

error = blkdev_issue_zeroout(bdev, start >> SECTOR_SHIFT,
- len >> SECTOR_SHIFT, GFP_KERNEL, flags);
+ len >> SECTOR_SHIFT, GFP_KERNEL,
+ flags | BLKDEV_ZERO_KILLABLE);
fail:
filemap_invalidate_unlock(inode->i_mapping);
inode_unlock(inode);
--
2.43.0